IN THE CLAIMS: 

Please AMEND claims 1-35; and 
Please ADD claim 36, as shown below. 



1 . (Currently Amended) A method for providing secure access to a packet data 



receiving a message from a terminal device connected to said-apacket data network; 
deriving a first source information from said message; 
deriving a second source information; 

comparing said first source information and second source information; and 
initiating a protection processing based on a result of said comparing ; and 
providing secure access to said packet data network based on said protection 



2. (Currently Amended) A method for providing secure access to a pack e t data 



receiving a message from a terminal device connected to said-a_packet data network; 
deriving a first source information from said message; 
deriving a second source information; 

comparing said first source information and second source information; and 
initiating a protection processing based on a result of said comparing ; and 




processing . 
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providing secure access to said packet data network based on said protection 
processing . 

3. (Currently Amended) A~The method according to claim 1 , wherein said 
second source information is a source address information derived from a packet data unit 
configured to convey said message, or from a security association set up between said 
terminal device and said packet data network. 

4. (Currently Amended) A -The method according to claim 1 , wherein said 
protection processing comprises a processing for dropping said message if the result of said 
comparing is that said first source information and said second source information do not 
indicate the same location. 

5. (Currently Amended) A ^The method according to claim 1, wherein said 
protection processing comprises a processing for dropping said message if said comparing 
leads to the result that said first source information and said second source information do 
not match. 

6. (Currently Amended) A- The method according to claim 1, wherein said first 
source information is an internet protocol address. 
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7. (Currently Amended) A- The method according to claim 6, wherein said 
message is a session initiation protocol message. 

8. (Currently Amended) A- The method according to claim 1 , wherein said 
second source information is at least a part of an internet protocol source address of an 
internet protocol datagram. 

9. (Currently Amended) A -The m ethod according to claim 1, wherein said 
second source information is at least a part of an internet protocol source address of an 
internet protocol datagram. 

10. (Currently Amended) A -The method according to claim 3, wherein said 
second source information is an internet protocol address bound to an integrity key of said 
security association. 

1 1 . (Currently Amended) A -The method according to claim 10, wherein said 
internet protocol address is stored in a database of a proxy server configured to route said 
message to said packet data network. 

12. (Currently Amended) A- The method according to claim 10, wherein said 
message is conveyed using a session initiation protocol level protection function. 
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1 3 . (Currently Amended) A network element for providing s e cur e access to a 
pack e t data network , said network e lement comprising: 

areceiving m e ans fo r unit configured to rec e iving r eceive a message from a terminal 
device connected to said network element; 

aderiving means fo r unit configured to d e riving derive a first source information from 
said message, and for deriving a second source information; 

^comparing means fo r unit configured to comparing compare said first source 
information and second source information; and 

^protecting m e ans fo r unit configured to initiating initiate a protection processing 
based on a comparing result of said comparing unit m eans and to provide secure access to a 
packet data network based on said protection processing . 

14. (Currently Amended) A /The network element according to claim 13, wherein 
said deriving m e ans unit is configured to derive said second source information from a 
packet data unit configured to derive said message or from a security association set up 
between said terminal device and said network element. 

15. (Currently Amended) A- The network element according to claim 13, wherein 
said deriving m e ans unit is configured to derive said first source information from a header 
portion of said message. 
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16. (Currently Amended) A -The network element according to any on e of claims 
43- claim 13 , wherein said protecting m e an s unit is configured to initiate a processing for 
dropping said message if said comparing result indicates that said first source information 
and said second source information do not indicate a same location. 

17. (Currently Amended) A- The network element according to any on e of claims 
44 claim 13 , wherein said protecting means unit is configured to initiate a processing for 
dropping said message if said comparing result indicates that said first source information 
and said second source information do not match. 

18. (Currently Amended) A -The network element according to any on e of claims 
44 claim 13 , wherein said deriving m e ans unit is configured to read said second source 
information from a database provided at said network element. 

19. (Currently Amended) A- The network element according to any on e of claims 
44 claim 13 , wherein said deriving m e ans unit is configured to derive said second source 
information by extracting an internet protocol source address from an internet protocol 
datagram. 

20. (Currently Amended) A- The network element according to claim 13, wherein 
said network element is a proxy server. 
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21 . (Currently Amended) A- The network element according to claim 20, wherein 
said proxy server is a proxy call state control function of an internet protocol mobility 
subsystem. 

22. (Currently Amended) A- The method according to claim 2, wherein said 
second source information is a source address information derived from a packet data unit 
configured to convey said message, or from a security association set up between said 
terminal device and said packet data network. 

23. (Currently Amended) A ^The method according to claim 2, wherein said 
protection processing comprises a processing for dropping said message if the result of said 
comparing is that said first source information and said second source information do not 
indicate the same location. 

24. (Currently Amended) A^ The method according to claim 23, wherein said 
protection processing comprises a processing for dropping said message if the result of said 
comparing is that said first source information and said second source information do not 
match. 

25. (Currently Amended) Ar The method according to claim 2, wherein said first 
source information is an internet protocol address. 
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26. (Currently Amended) A- The method according to claim 2, wherein said 
message is a session initiation protocol message. 

27. (Currently Amended) A- The method according to claim 2, wherein said 
second source information is at least a part of an internet protocol source address of an 
internet protocol datagram. 

28. (Currently Amended) A /The method according to claim 2, wherein said 
message is conveyed using a session initiation protocol-level protection function. 

29. (Currently Amended) A ^The network element according to claim 14, wherein 
said deriving means unit is configured to derive said first source information from a header 
portion of said message. 

30. (Currently Amended) A ^The network element according to claim 14, wherein 
said protecting means unit is configured to initiate a processing for dropping said message if 
said comparing result indicates that said first source information and said second source 
information do not indicate the same location. 

3 1 . (Currently Amended) A- The network element according to claim 14, wherein 
said protecting means unit is configured to initiate a processing for dropping said message if 
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said comparing result indicates that said first source information and said second source 
information do not match. 

32. (Currently Amended) A- The network element according to claim 14, wherein 
said deriving mean s unit is configured to read said second source information from a 
database provided at said network element. 

33. (Currently Amended) A- The network element according to claim 14, wherein 
said deriving m e an s unit is configured to derive said second source information by extracting 
an internet protocol source address from an internet protocol datagram. 

34. (Currently Amended) A- The network element according to claim 14, wherein 
said network element is a proxy server. 

35. (Currently Amended) A- The network element according to claim 34, wherein 
said proxy server is a proxy call state control function of an internet protocol mobility 
subsystem. 

36. (New) A network element, comprising: 

receiving means for receiving a message from a terminal device connected to said 
network element; 
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deriving means for deriving a first source information from said message, and for 
deriving a second source information; 

comparing means for comparing said first source information and second source 
information; and 

protecting means for initiating a protection processing based on a comparing result of 
said comparing means and for providing secure access to a packet data network based on 
said protection processing. 
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